Courseiva

Conditional Access Sign-in Frequency Session Control

A company uses Microsoft Entra ID. They have a critical application that requires additional security. The security team wants to enforce multifactor authentication (MFA) for every access to the application, but they also want users to reauthenticate with MFA if a session lasts longer than 60 minutes, regardless of device compliance. Which Conditional Access control should the administrator configure?

Quick Answer

The key distinction this question is testing is grant controls versus session controls within Conditional Access — two different categories of setting that are easy to conflate. Grant controls decide whether access is allowed at all at the moment of sign-in, which is where a blanket 'require MFA' requirement lives, but a grant control only fires once per session and has nothing to say about what happens later in that same session. Sign-in frequency is a session control, and it operates on a completely different axis: it forces the user to reauthenticate, MFA included, once a session has been active longer than a defined interval — 60 minutes in this scenario — regardless of whether the device remains compliant or the original sign-in was already fully authenticated. That's precisely why device compliance doesn't factor into the answer here: sign-in frequency is a time-based trigger, not a device-state check, so it keeps re-prompting on schedule even for a device that never stops being compliant. Any scenario describing a maximum session duration or a mandate to periodically re-verify identity during a long-lived session, rather than a one-time access decision, is pointing at sign-in frequency specifically.

⚠ Common exam trap

Watch out — candidates often confuse 'Grant controls' (which enforce conditions at sign-in) with 'Session controls' (which manage behavior after sign-in), leading them to select 'Require multifactor authentication' instead of 'Sign-in frequency' for time-based reauthentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session control: Sign-in frequency

The requirement to force reauthentication with MFA after a specific time period (60 minutes) is a session-level control, not a grant control. The 'Sign-in frequency' session control in Conditional Access allows administrators to define how often a user must reauthenticate, including re-prompting for MFA, regardless of device compliance. This directly meets the scenario's need for a time-based reauthentication policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant control: Require multifactor authentication

    Why it's wrong here

    Require multifactor authentication enforces MFA at sign-in but does not force reauthentication after 60 minutes; that interval is set by the Sign-in frequency session control. Require multifactor authentication is correct when MFA must simply be demanded for every access without a reauthentication interval.

  • ✓

    Session control: Sign-in frequency

    Why this is correct

    Sign-in frequency is a session control that forces reauthentication after a set interval, here 60 minutes, irrespective of device compliance state. MFA is then re-enforced at each reauthentication, matching the requirement for periodic MFA regardless of compliance.

  • ✗

    Session control: Application enforced restrictions

    Why it's wrong here

    Application enforced restrictions passes device or client information to the application for it to limit access; it neither demands MFA nor sets a reauthentication interval. Sign-in frequency governs reauthentication timing. Application enforced restrictions suits restricting Exchange Online or SharePoint access from unmanaged devices.

  • ✗

    Grant control: Require device to be marked as compliant

    Why it's wrong here

    Requiring a compliant device gates access on device state, which the scenario explicitly excludes, and it does not enforce MFA or a 60-minute reauthentication interval. Sign-in frequency sets that interval. Device compliance is right when only managed, compliant devices may reach the application.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization uses Microsoft Entra ID and wants to require users to re-authenticate every 4 hours when accessing a critical financial application, even if the user already has an active sign-in session. Which Conditional Access control should be configured?

medium
  • A.Grant control 'Require multi-factor authentication'
  • ✓ B.Session control 'Sign-in frequency'
  • C.Session control 'Persistent browser session'
  • D.Grant control 'Require device to be marked as compliant'

Why B: The 'Sign-in frequency' session control in Conditional Access allows administrators to specify the time interval after which a user must re-authenticate, even if they have an active session. By setting this to 4 hours, the organization ensures that users re-authenticate before accessing the critical financial application, overriding any existing session tokens.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.